SearchLeak, where a crafted link made an enterprise copilot search the victim's own mailbox and push the results out
Varonis disclosed in June 2026 that a query parameter in a crafted link was interpreted by Microsoft 365 Copilot Search as instructions. Chained with a rendering race condition and a server side request forgery, one click made the copilot search the victim's mailbox and send the results out through an image request, using the victim's full directory permissions.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AIL-2026-0020
- Kind
- Exfiltration
- Jurisdiction
- United States
- Last verified
- Added
- The research states that the copilot interprets the query parameter as instructions and searches the victim's mailbox.
- The chain combined parameter to prompt injection, an HTML rendering race condition and a server side request forgery in a first party service.
- The enterprise copilot runs with the user's full directory permissions, so the attacker inherited reach into mail, calendar, document libraries and file storage.
- The research notes the user sees only a response that may look odd, by which time the data has already gone.
- Microsoft assigned CVE-2026-42824 and patched it with no user action required.
Dimension by dimension
7 dimensions, each one stated, silent or open
Identity, Authorization, Limits, Human approval, Logging and audit, Revocation, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- IdentitySilent
- A URL query parameter carried instruction level authority inside the agent.Varonis Threat Labs, SearchLeak, primary source, 15 June 2026.
- AuthorizationSilent
- The copilot's full directory permissions were inherited by whoever controlled the link.Varonis Threat Labs, SearchLeak, primary source, 15 June 2026.
- LimitsSilent
- The content security policy was bypassed through a first party request forgery, so the egress boundary failed on a trusted domain.Varonis Threat Labs, SearchLeak, primary source, 15 June 2026.
- Human approvalSilent
- One click was the whole interaction; nothing confirmed the search or the outbound request.Varonis Threat Labs, SearchLeak, primary source, 15 June 2026.
- Logging and auditSilent
- The user's only signal was an odd looking answer, which is not a detection control.Varonis Threat Labs, SearchLeak, primary source, 15 June 2026.
- RevocationStated
- The vendor patched the chain on its own service with no user action required.Varonis Threat Labs, SearchLeak, primary source, 15 June 2026.
- AccountabilityStated
- A CVE was assigned and named researchers published the chain with a timeline.Varonis Threat Labs, SearchLeak, primary source, 15 June 2026.
What it changes
For a team deploying an agent
An allowlist of trusted domains is not an egress control when a trusted domain will fetch a URL for you. Ask your vendor which outbound channels an agent can reach and what closes them deterministically rather than by classifier. On your side, reduce what the copilot can see: scope its directory permissions to the libraries a role needs, so one click reaches less.
Sources
What this record was verified against
- Varonis Threat Labs, SearchLeakPrimary · 15 June 2026
Related
Records that sit beside this one
EchoLeak, a zero click chain that pulled tenant data out of Microsoft 365 Copilot
United States · verified 15 September 2026
Microsoft's advisory for CVE-2025-32711 states the vulnerability has already been fully mitigated and that there is no action for users of the service to take.
CoSnitch, where an injected instruction wrote itself into a copilot's persistent memory and re armed every session
United States · verified 15 September 2026
The research states the injected instruction remains active in every future session for that user unless the user manually navigates to memory settings and deletes it.
GrafanaGhost, where stored data became an instruction and the assistant posted observability data to an external server
Global · verified 15 September 2026
The research states that because the exploit ignores model restrictions and operates autonomously, sensitive enterprise data can be leaked silently.
A support agent invented a policy its company did not have, and customers cancelled over it
United States · verified 15 September 2026
A company representative stated publicly that there is no such policy and that users are free to use the product on multiple machines.
A vendor's own red team made a browser agent send a resignation letter for the user, then showed the fixed agent refusing
United States · verified 15 September 2026
The vendor's own account states that the out of office reply never gets written and the agent resigns on behalf of the user instead.
A browser agent read the local file system and shipped it out while still answering the user normally
United States · verified 15 September 2026
The research states the agent autonomously accesses the local file system and exfiltrates the contents to an attacker controlled endpoint while still returning the expected response.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0020 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Incident Ledger (as of 15 September 2026), searchleak, where a crafted link made an enterprise copilot search the victim's own mailbox and push the results out.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). SearchLeak, where a crafted link made an enterprise copilot search the victim's own mailbox and push the results out. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0020-searchleak-one-click-turned-copilot-search-into-theft
- MLA
- "SearchLeak, where a crafted link made an enterprise copilot search the victim's own mailbox and push the results out." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0020-searchleak-one-click-turned-copilot-search-into-theft.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "SearchLeak, where a crafted link made an enterprise copilot search the victim's own mailbox and push the results out." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0020-searchleak-one-click-turned-copilot-search-into-theft.
- Permalink
- https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0020-searchleak-one-click-turned-copilot-search-into-theft
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.
Back to the full ledger, or every record for United States and every exfiltration record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.